Alison Davis and Peter Kurtz Port Based Network Authentication in a Lab Environment QUESTNet 2000.

Slides:



Advertisements
Similar presentations
Back Office Support System(BOSS) of High Speed Internet Service Myeong Hwan Park
Advertisements

SUNNYSLOPE SCHOOL PROJECT BY SWG ENGINEERING Group Members CINDY CINDY STEVE STEVE GALLO GALLO York Technical College Cisco Networking ACADEMY.
Module CSY3021 Network Planning and Programming RD-CSY /09 1.
BTT 101 / 2O1 Lesson 10 Dundas Valley Secondary Mr. Young.
The Nomadic Network Providing Secure, Scalable and Manageable Roaming, Remote and Wireless Data Services Josh Howlett & Nick Skelton Information Services,
Network Access and 802.1X Klaas Wierenga SURFnet
E-commerce and Information Technology in Hospitality and Tourism Chapter 3 Connecting to the World Copyright 2004 by Zongqing Zhou, PhD Niagara University.
Hands-On Microsoft Windows Server 2003 Administration Chapter 11 Administering Remote Access Services.
Computers © 2005 Prentice-Hall, Inc.Slide 1. Computers Chapter 6 Networks and Networking © 2005 Prentice-Hall, Inc.Slide 2.
Wi-Fi Structures.
Lesson 14 – DESIGNING A NETWORK. Assessing Network needs Meeting Network needs OVERVIEW.
Understanding Networks I. Objectives Compare client and network operating systems Learn about local area network technologies, including Ethernet, Token.
Data Networking Fundamentals Unit 7 7/2/ Modified by: Brierley.
INTRODUCTION TO COMPUTER NETWORKS Navpreet Singh Computer Centre Indian Institute of Technology Kanpur Kanpur INDIA (Ph : ,
Data Centers and IP PBXs LAN Structures Private Clouds IP PBX Architecture IP PBX Hosting.
1. A router is a device in computer networking that forwards data packets to their destinations, based on their addresses. The work a router does it called.
Andrew Fuqua 3/4/2015 LTEC A network HUB is a device that is used to link multiple devices over a network. The HUB is not a great choice when shopping.
Module 11: Supporting Remote Users. Overview Establishing Remote Access Connections Connecting to Virtual Private Networks Configuring Authentication.
1 Chapter 7 - Networking Fundamentals Computer network: – Two or more computers connected together Each is a Node (other nodes: printers, network devices,
Chapter 11: Dial-Up Connectivity in Remote Access Designs
ITGS Networks Based on the textbook “Information Technology in a Global Society for the IB Diploma” by Stuart Gray.
Using RADIUS Within the Framework of the School Environment Ed Register Consultant April 6, 2011.
Virtual Private Networks (Tunnels). When Are VPN Tunnels Used? VPN with PPTP tunnel Used if: All routers support VPN tunnels You are using MS-CHAP or.
Basic Network Training. Cable/DSL Modem The modem is the first link in the chain It is usually provided by the ISP and often has a coax cable connector.
The Basics of Networking. Rick Graziani What is networking? Communication! An interconnection of computers and other devices: –Printers.
Computer Networking From LANs to WANs: Hardware, Software, and Security Chapter 6 Network Design and Troubleshooting Scenarios.
1 Networks, advantages & types of What is a network? Two or more computers that are interconnected so they can exchange data, information & resources.
Unified Student-Centric Authentication and Authorization Nathan Wilder Special Assistant - Technology Office of the CIO.
Configuring Routing and Remote Access(RRAS) and Wireless Networking
PowerPoint Presentation to Accompany Chapter 9 Networks & Communications Visualizing TechnologyCopyright © 2014 Pearson Education, Inc. Publishing as Prentice.
MikroTik Experience Overview - Wireless ISP Solutions
Chapter 5 Networks Communicating and Sharing Resources
Chapter 1 An Introduction to Networking
Chapter 7: Using Windows Servers to Share Information.
Module 9: Planning Network Access. Overview Introducing Network Access Selecting Network Access Connection Methods Selecting a Remote Access Policy Strategy.
1 Chapter 7 - Networking Fundamentals Computer network: – Two or more computers connected together Each is a Node (other nodes: printers, network devices,
70-411: Administering Windows Server 2012
Computer Concepts 2014 Chapter 5 Local Area Networks.
 Spring 2011  CSCI 27 Computer Networking Course Overview.
Technology Strategies for the Hospitality Industry© 2005 Pearson Education, Inc Nyheim, McFadden, & Connolly Upper Saddle River, New Jersey Networks.
LAN Design of a Local High School Martin Kucek Chris C. Yu Sandy Ramirez Cisco TCS Project – Semester 3 © 2001 Martin Kucek / Chris C. Yu / Sandy Ramirez.
Module 11: Remote Access Fundamentals
NETWORKING COMPONENTS AN OVERVIEW OF COMMONLY USED HARDWARE Christopher Johnson LTEC 4550.
1 Second ATLAS-South Caucasus Software / Computing Workshop & Tutorial October 24, 2012 Georgian Technical University PhD Zaza Tsiramua Head of computer.
University of Palestine Faculty of Applied Engineering and Urban Planning Software Engineering Department INTRODUCTION TO COMPUTER NETWORKS Dr. Abdelhamid.
IP TELEPHONY AT THE AUSTRALIAN CATHOLIC UNIVERSITY A CASE STUDY WIL DANIELS MANAGER, INFORMATION TECHNOLOGY SERVICES.
DSL-520B. What is a DSL-520B -ADSL2+ MODEM ROUTER -1 RJ-11 ADSL port, 1 RJ-45 10/100BASE-TX Ethernet LAN port with auto MDI/MDIX -Factory reset button.
Introduction to Information Systems Lecture 06 Telecommunications and Networks Business Value of Networks Jaeki Song.
Cooperative Education – Networking Fall 2009 Network Team Saigon Institute of Technology.
2 …it’s even got its own trade show …it’s expected to be rapidly deployed… WW Market forecast (millions) The truth about gigabit networking It’s a big.
Overview WIALAN Applications Products Administration system
Supporting a Wireless Network By Gareth Ayres.
Higher Computing Networking. Networking – Local Area Networks.
Peter Kurtz Manager, Network Operations Centre.
1 Syllabus at a glance – CMCN 6103 Introduction Introduction to Networking Network Fundamentals Number Systems Ethernet IP Addressing Subnetting ARP DNS.
WELCOME TO THE WORLD OF NETWORK CLICKTECHSOLUTION.COM.
Agenda Overview of Seneca Computer System File Servers / Student Computer Accounts Telnet application How to Logon to Learn / Phobos accounts How to Change.
2/18/2016Fatimah AlAkeel - Network 11 Introduction to Networks.
Infrastructure for the DBA: An Introduction Peter Shore SQL Saturday Chicago 2016.
Chapter 7: Using Windows Servers
Chapter 1 Introduction to Networking
ICT II Unit 6 Networking.
Module 9: Configuring Network Access
Data Networking Fundamentals
Introduction to Networks
Introduction to Networks
Introduction to Networks
Networks and Topologies
Campus Software Deployment Solution
Introduction to Networks
Presentation transcript:

Alison Davis and Peter Kurtz Port Based Network Authentication in a Lab Environment QUESTNet 2000

Alison Davis and Peter Kurtz Contents Introduction Overview of QUT’s network Technical part of the LAS Project Support part of the LAS Project

Alison Davis and Peter Kurtz Introduction Laptop Access Project started in 1999 Provide Laptop Access in QUT Labs Faster and better access Demand for student labs Economic considerations

Alison Davis and Peter Kurtz Overview of the QUT Network Potential of 34,000 users - 30K students 4K staff x PCs / Workstations 90 Central Servers, 30 x Faculty Servers 2 x WAN ATM Switches 3 x Legacy Routers, 4 x ATM Router Engines 46 x ATM Switches 189 x Ethernet Switches 370 x Ethernet Hubs 48 x Terminal Servers 600 x Digital / Analog Modems

Alison Davis and Peter Kurtz Kelvin Grove Campus 34Mbps Mt Cootha QUT Wide Area Network (Voice/Data) - May 2000 Gardens Point Campus Carseldine Campus 4 x 2Mbps 155Mbps Margaret St Offices 64k UQ 34Mbps PABX AARNET DIALIN ACCESS 6 x 2Mbps 2 x 2Mbps 2Mbps ATM Switch Legacy Router Merivale St PSTN / ISDN Peel St KG Offices (4) Switch 2Mbps Radio Link 2Mbps Radio Links GU 34Mbps USQ Adelaide St 34Mbps

Alison Davis and Peter Kurtz Network Projects 2000 Installing Accellar router switches into the core of data network. VoIP trials Carseldine WAN upgrade to155Mbps Microwave Links reused for redundancy

Alison Davis and Peter Kurtz QUT Wide Area Network (Voice/Data) - Future Mt Cootha Gardens Point Campus Carseldine Campus Kelvin Grove Campus GU 34Mbps 155Mbps 34Mbps 6Mbps 12Mbps ATM Switch Legacy Router AARNET UQ

Alison Davis and Peter Kurtz Current Networking Issues High Availability and High Bandwidth  Integrating voice over the data network Network Performance  Wire speed routing  IP only backbone Network Security  Breach Monitoring within the LAN  Secure Management LAN  Leaf node (port based) authentication

Alison Davis and Peter Kurtz Laptop Access Project Requirements Easy to use authenticated laptop access  Given technical and financial constraints. Network Authentication  Use QUT Access username, password. Network Access and Performance  Same as in a standard public access lab. Before Authentication  Network access must be completely restricted, including other unauthenticated ports.

Alison Davis and Peter Kurtz Possible Client End Solutions Laptop to switch authentication using:  1. Microsoft(NetBIOS) or NetWare Client  2. Browser or telnet Client  3. Extensible Authentication Protocol - EAP Laptop to server authentication  Microsoft or Browser client  Server requests port movement from default VLAN to the authenticated VLAN

Alison Davis and Peter Kurtz Network Authentication Process Laptop/PC Default Port Virtual LAN Authenticated Virtual LAN Central Dynamic Address Allocation Server (DHCP) Network Gateway (Router) Alcatel Ethernet Switch Central Authentication Server (RADIUS) Internal Web and Telnet Server 1 2 3

Alison Davis and Peter Kurtz IP, Gateway Address Primary DNS Secondary DNS - Switch IP Network Authentication Process - Detail DHCP Request Central DCHP Server DHCP Reply 1 2 Switch Internal Web & Telnet Server DNS [QUTAccess ] DNS [Switch IP Addr] Username, Password Auth Successful Central RADIUS Server Front End for Oracle DB ORACLE Database Stores: QUT Access Username Password

Alison Davis and Peter Kurtz Current Solution Specifications ISC DHCP Server Ver 2.0  Internet Software Consortium - RADIUS Server Radiator  Open Systems Consultants - Oracle Database ver 8 with perl DBI ALCATEL Switches  Omnistack 4024,5024, Omniswitch router OSR  Current software GA  Standard Telnet, Netscape, IE 4,5  Win95,98,NT,Win2000, MacOS, Linux

Alison Davis and Peter Kurtz Radius Log Processor - snapshot

Alison Davis and Peter Kurtz Alcatel Solution Switch authentication reliability  software, hardware problems Vendor support was good Scalability is Costly

Alison Davis and Peter Kurtz Future Direction QUT authentication backend change  Directory Service replaces oracle db  User profile detail VLAN  LDAP replace RADIUS Goals for switch vendors  Authentication before DHCP  A solution for Operations Systems apart from Win2K  A solution for all L2 Access - Ethernet & Wireless

Alison Davis and Peter Kurtz From the technical detail to the bigger picture….. Technical Support Usage Cost effectiveness

Alison Davis and Peter Kurtz What other universities are doing User services list March 2000 University of Melbourne CAUDIT list June 2000 Information from 23 universities

Alison Davis and Peter Kurtz Institutional Responses Most universities are at least considering laptop access for students (17/23) à 9 yes à 8 Soon/very small à 6 no Demand has been much lower than expected Many see wireless as the future direction

Alison Davis and Peter Kurtz QUT laptop access areas Law Library. September 1999 Graduate School of Business teaching facilities. Semester Gardens Point Library. June-July 2000 Student superlab – 350 ports – October 2000

Alison Davis and Peter Kurtz Law library usage statistics

Alison Davis and Peter Kurtz Law Library usage statistics (cont)

Alison Davis and Peter Kurtz Law library usage statistics (cont) 21 students successfully used the service 9 students only used it on one day 1 student used it on 23 days Maximum of 5 users on any one day Usage slowly increasing

Alison Davis and Peter Kurtz Support issues Hired laptops (preconfigured) Only connect at QUT laptops (configure once) Modem + QUT connection laptops (minor adjustments) Work laptops. Major adjustments. Hire network cards or USB connectors

Alison Davis and Peter Kurtz Promotion Signage Official launch Position Competition Feedback

Alison Davis and Peter Kurtz

What we’ve learnt Support Demand - convenience Promotion Equity Laptop Security Technical - hardware and management

Alison Davis and Peter Kurtz Likely future Wireless Client software will be inbuilt Interchangable with desktops Establish cost effectiveness Benchmark student access to the university network